Import table
advapi32.dll
OpenSCManagerA, OpenServiceA, QueryServiceConfigA, CloseServiceHandle, RegDeleteValueW, LookupAccountSidW, ConvertSidToStringSidW, GetSidLengthRequired, InitializeSid, EqualSid, CopySid, IsValidSid, GetTokenInformation, GetSidSubAuthorityCount, GetSidSubAuthority, DuplicateTokenEx, ConvertStringSidToSidW, GetLengthSid, SetTokenInformation, CreateProcessAsUserW, CryptCreateHash, CryptGetHashParam, CryptHashData, CryptDestroyHash, CryptAcquireContextW, CryptReleaseContext, OpenProcessToken, RegSetValueExW, RegEnumValueW, RegEnumKeyExW, RegCreateKeyExA, RegCreateKeyExW, RegSetValueExA, RegQueryInfoKeyW, RegDeleteKeyW, RegEnumKeyExA, RegDeleteValueA, RegQueryValueExA, RegOpenKeyExA, RegQueryValueExW, RegOpenKeyExW, RegCloseKey
kernel32.dll
DllMain
ole32.dll
CoTaskMemAlloc, CreateStreamOnHGlobal, CLSIDFromString, CoCreateInstance, CoTaskMemFree, CoUninitialize, CoGetObject, StringFromGUID2, CoTaskMemRealloc, CoGetClassObject, CoInitialize
psapi.dll
GetModuleBaseNameW, EnumProcesses, EnumProcessModules
shell32.dll
ShellExecuteExW, ShellExecuteW, SHGetFolderPathW
shlwapi.dll
PathAppendW
user32.dll
GetActiveWindow, LoadStringW, CharNextW, wsprintfW, UnregisterClassA
userenv.dll
UnloadUserProfile
version.dll
VerQueryValueA, GetFileVersionInfoA, GetFileVersionInfoSizeA
wintrust.dll
WinVerifyTrust
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer